![]() |
IOBit Software
|
|
|
||||||
| Malware Removal Malware removal forum. Please see the READ ME FIRST thread before you post. Forum is staffed by a small number of volunteers, please be patient. |
![]() |
|
|
Thread Tools | Display Modes |
|
#1
|
|||
|
|||
|
Hi, this is my first dealing with a rootkit alert; I have prevx installed and it says one of my music files that is several months old might contain a rootkit. How would I know if it really is a bad rootkit or one of the legal ones out there or if it's just a false positive? I've tried posting this message with the file attached but it won't post it for some reason. Oh yes, I also scanned the rest of my system and all else is clean.
here is what Gmer found: GMER 1.0.12.12011 - http://www.gmer.net Rootkit scan 2008-12-23 08:47:52 Windows 5.1.2600 Service Pack 2 ---- User code sections - GMER 1.0.12 ---- .text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[1712] kernel32.dll!SetUnhandledExceptionFilter 7C84467D 5 Bytes JMP 0056DBBD C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe ---- Devices - GMER 1.0.12 ---- Device \FileSystem\Cdfs \Cdfs IRP_MJ_FILE_SYSTEM_CONTROL [A11DE912] DLAIFS_M.SYS ---- Files - GMER 1.0.12 ---- ADS C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34 ---- EOF - GMER 1.0.12 ---- Not sure if those are actual rootkits or not so hopefully you can help with that. but TrendMicro's Rootblaster didn't find anything. Ok in the mean time I've also used the BlackLight rootkit scanner & also panda's rootkit scanner and both came back with zero rootkits. Any help would be appreciated; thank you. Mike |
| Sponsored links |
|
|
|
#2
|
|||
|
|||
|
ok well Prevx got back to me and it seems the music file was a false positive. Are the files that Gmer found also false positives? I sure hope so.
|
|
#3
|
||||
|
||||
|
Welcome to Major Geeks!
Quote:
The first is not a problem. DLAIFS_M.SYS is a Drive Letter Access Component from Sonic Solutions which is software you have on your PC for you CD/DVD drive.However the ADS detection (ADS = Alternate Data Stream) is not normal. And you really should do a check on your PC to determine if any malware is the cause of this. I recommed that you work thru the below. Please follow the instructions in the below link and attach the requested logs when you finish these instructions. READ & RUN ME FIRST. Malware Removal Guide
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#4
|
|||
|
|||
|
Thank you very much; yea after I did some searching I found that was a file for my sonic drive; but figured I'd leave it up there just in case; wsn't sure if it could become infected or not. Ok I ran all the stuff you told me to and am attaching the log files here. I couldn't use the spybot search & destroy though due to it being incompatible with my Trend Micro Pc-Cillin program. the others I used though. Fingers crossed everything is clean.mbam-log-2008-12-26 (09-21-50).txt
SUPERAntiSpyware Scan Log - 12-26-2008 - 09-11-17.log ComboFix.txt |
|
#5
|
|||
|
|||
|
|
| Sponsored links |
|
|
|
#6
|
|||
|
|||
|
one thing that is strange though; after I ran all these tests; i was wanting to check "msconfig" so i typed it into the "run" window & it told me it couldn't be found. Also, I restarted the pc and it went to the window asking how I wanted to boot the operating system before it'd start up as normal so I had to do a system restore to yday grrr. Any ideas?
|
|
#7
|
|||
|
|||
|
ok now this is annoying; now prevxcsi found this file - is it also a false positive?
it's in C: Windows:system32:swreg.exe which I found is some sort of reg editor from SteelWerX. |
|
#8
|
||||
|
||||
|
Quote:
Quote:
You did not install the version of SUPERAntiSpyware given in the READ & RUN ME. You are way out of date. You need to uninstall what you have, and then download, install, and update the version given in the link in the READ & RUN ME. You do have a couple things to do. Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups. Uninstall the below old versions of software: Java(TM) SE Runtime Environment 6 Update 1 Viewpoint Media Player <-- should have been uninstalled in step 1 of the READ ME Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now: O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime After clicking Fix, exit HJT. Now run Ccleaner! Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). Then attach the below log:
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter Last edited by chaslang; 12-28-08 at 01:45.. |
|
#9
|
||||
|
||||
|
False postive. PrevX has a lot of false positive issues. I suggest not using it.
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#10
|
|||
|
|||
|
ok I'm sorry I didn't remove that viewpoint player before hand; I must have not seen that step in the Read Me section. I did as you requested and here are the 2 logs you wanted; one thing though- I didn't get this to come up- This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime After clicking Fix, exit HJT. I ran the MGtool but I didn't see anything come up regarding the hijackthis so I went in and opened it myself & when it scanned my pc it didn't list the "O4-HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.ex" so I left that alone just in case; I will do the CCleaner right now. I did remove the prevx program as you suggested & I can't say I'm sad to see it go considering it scared me twice now this week. Would you also take a look at this screen shot please & tell me which folders & files I can safely remove; I don't want to do anything that'll screw my system up; thank you very much for your help. MGlogs.zip SUPERAntiSpyware Scan Log - 12-28-2008 - 07-47-26.log Image1.jpg |
| Sponsored links |
|
|
|
#11
|
||||
|
||||
|
Your logs are clean.
If you are not having any other malware problems, it is time to do our final steps:
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#12
|
|||
|
|||
|
thank you so much for your help; I really appreciate it & i've done all you told me to do
Have a great new year. |
|
#13
|
||||
|
||||
|
You're welcome. Surf safely!
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
![]() |
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Rootkit.Agent and Rootkit.Bugle, yeah I know... | filipetolhuizen | Malware Removal | 12 | 10-03-08 00:16 |
| Rootkit.bagle and Rootkit.Agent - No Internet, No Safe Mode, No Antivirus | raremedium | Malware Removal | 14 | 04-19-08 22:48 |
| Rootkit | Vast41 | Malware Removal | 5 | 09-15-06 09:06 |
| RootKit | torbob | Malware Removal | 1 | 07-20-06 22:58 |